All Products
Search
Document Center

Alibaba Cloud Service Mesh:Pre-2023 release notes

Last Updated:Jun 26, 2026

These release notes cover Service Mesh (ASM) releases before 2023.

December 2022

Feature

Description

Region

Supported Istio version

Edition

References

Adaptive configuration push optimization

ASM provides a managed, on-demand xDS configuration push capability. It analyzes access logs in real time to identify the sidecar resource configurations that services need. This improves xDS push efficiency.

All

v1.15 and later

Enterprise, Ultimate

Optimize control plane push efficiency with adaptive xDS

Custom authorization services for ASM gateways

You can configure an external custom authorization service for an ASM gateway in a streamlined process. This simplifies integration with external authorization systems.

All

v1.15 and later

Enterprise, Ultimate

Use a custom authorization service on an ASM gateway

Service level objectives (SLOs) for enhanced observability

Defining a service level objective (SLO) for an application in ASM automatically generates Prometheus rules, which you can then import into Prometheus to monitor your SLO.

All

v1.15 and later

Enterprise, Ultimate

Configure an SLO for an application

OPA engine upgrade

The OPA engine has been upgraded to version 0.46.1, which supports more OPA features.

All

v1.15 and later

All

Use OPA policies for fine-grained access control

November 2022

Feature

Description

Region

Istio version

Edition

Documentation

Support for Istio 1.15.

Compatible with the community Istio 1.15 series and supports Kubernetes 1.21 to 1.25.

All

v1.15

All

None

Enhanced security for ASM gateways with blacklist and whitelist support.

Supports centralized configuration of blacklists and whitelists for ASM gateways.

All

v1.15 and later

Enterprise, Ultimate

Configuring blacklists and whitelists on ASM gateways

Support for TPROXY mode for inbound traffic interception.

  • Enables TPROXY mode for transparent traffic interception, which preserves the source IP address and port.

  • This feature can be configured at the global, namespace, and workload levels.

All

v1.15 and later

Enterprise, Ultimate

Obtaining the client source IP in a service mesh

Support for advanced configuration of distributed tracing.

You can configure advanced distributed tracing features, such as the sampling rate and custom tags.

All

v1.15 and later

Enterprise, Ultimate

None

Support for generating SLOs from Prometheus metrics.

You can use metrics reported by Istio to define SLOs and their corresponding alert rules.

All

v1.15 and later

Enterprise, Ultimate

SLO overview

Support for configuring TLS versions on ASM gateways.

You can configure TLS versions on an ASM gateway to enhance gateway security.

All

v1.14 and later

Enterprise, Ultimate

Configuring TLS versions on an ASM gateway

October 2022

Feature

Description

Region

Supported Istio version

Edition

References

CNI-based traffic redirection for enhanced security.

  • You can configure traffic redirection with the CNI plug-in, which moves iptables rule configuration from pods.

  • The CNI plug-in requires no privileged permissions, reducing operator permission requirements and enhancing the security of Service Mesh.

All regions

v1.14 and later

Enterprise, Ultimate

Enable the CNI plug-in to enhance security

Simplified configuration for selective service discovery.

Define the service discovery scope for Service Mesh by selecting data plane namespaces to simplify configuration and improve control plane performance.

All regions

v1.14 and later

All

Improve push efficiency with service discovery selectors

Enhanced mesh topology.

The mesh topology feature monitors network traffic to infer service topology and analyze the mesh, helping you understand the structure and health of your Service Mesh.

All regions

v1.14 and later

All

View application mesh topology

ASM security policy.

  • ASM encapsulates native Istio security resources, providing a single point of configuration for common security scenarios.

  • The policy supports OpenID Connect (OIDC) single sign-on and JSON Web Token (JWT) authentication. You can apply policies to multiple workloads and define the request scope for the rules.

All regions

v1.14 and later

Enterprise, Ultimate

ASM security policies overview

Enhanced observability for throttling.

This feature extends the local throttling capability by adding metric collection settings.

All regions

v1.14 and later

Enterprise, Ultimate

Configure local throttling in the Traffic Management Center

Enhanced trial mode for security policies.

You can apply security policies in trial mode, allowing ASM administrators to validate policies before they take effect.

All regions

v1.14 and later

All

Use trial mode for ASM authorization policies

Application management for edge clusters.

You can create a managed edge cluster in the Service Mesh console and manage its applications with Service Mesh (ASM).

All regions

v1.14 and later

Enterprise, Ultimate

Manage ACK Edge cluster applications

Traffic management in lane mode.

Create multiple traffic-isolated environments to ensure safe releases and support the parallel development of multiple service versions.

All regions

v1.14 and later

Enterprise, Ultimate

Use traffic management in lane mode

September 2022

Feature

Description

Region

Supported Istio version

Edition

References

ASM Competence Center

The ASM console now includes a Competence Center for an overview of ASM's ecosystem integration capabilities.

All

All

All

ecosystem integration

Service warm-up

This feature lets new instances warm up before receiving traffic, ensuring a graceful service startup.

All

v1.14 and later

Enterprise Edition, Ultimate Edition

Use the ASM slow start warm-up feature

Trial run mode for security policies

You can now apply security policies in trial run mode to validate their effects before enforcement.

All

v1.14 and later

All

Use trial run mode for ASM authorization policies

Enhanced AccessLog format editing

You can now add latency-related parameters when editing the AccessLog format for latency analysis.

All

All

All

None

Sidecar proxy enhancements

  • You can now set default values for global sidecar proxy settings.

  • ASM now provides recommended values for sidecar proxy lifecycle configuration.

  • To simplify configuration, the sidecar proxy configuration views for namespaces and workloads are now unified.

All

All

All

Sidecar proxy management

Support for multiple JWT algorithms

Request authentication now supports multiple JWT algorithms, giving administrators more flexibility.

All

v1.13 and later

All

JWT FAQ

OIDC integration for single sign-on

You can now configure single sign-on (SSO) for applications in your mesh by using external authorization to integrate with OIDC providers. Both Alibaba Cloud IDaaS and self-managed identity providers are supported.

All

v1.13 and later

All

August 2022

Feature

Description

Region

Supported Istio version

Edition

References

Support for Istio 1.14

  • Compatible with the community Istio 1.14 series and Kubernetes versions 1.21 to 1.24.

  • Enhances mesh diagnostics to improve self-service troubleshooting efficiency.

  • Enhances mesh topology rendering to show call relationships between services and related mesh information from multiple perspectives.

  • Fully supports third-party tokens in ACK clusters for enhanced workload security.

  • Introduces a plug-and-play plug-in marketplace for customizing Envoy filters.

All regions

v1.14

All

zone-aware routing

Enables zone-aware routing without modifying application code. This minimizes service-to-service latency by directing traffic to instances within the same availability zone whenever possible.

All regions

v1.13 and later

Enterprise Edition, Ultimate Edition

Enable zone-aware routing

Enhanced ASM gateway features and an optimized UI

  • Adds support for route-level circuit breaking.

  • Optimizes the UI for managing domain names, certificates, upstream services, and routes.

All regions

v1.13 and later

Enterprise Edition, Ultimate Edition

Use ASM route-level circuit breaking

July 2022

Feature

Description

Region

Supported Istio version

Edition

References

New region

ASM is now available in the Philippines (Manila) region.

Philippines (Manila)

1.13 and later

Standard, Enterprise, and Ultimate

Supported regions

Support for Istio 1.13

Component versions have been updated.

All regions

1.13

Standard, Enterprise, and Ultimate

None

Canary release for the Istio control plane

You can now perform a canary release for the Istio control plane. This method provides a smoother update experience than an in-place update, ensures control plane availability, and supports quick rollbacks.

Note

This feature is in canary release.

All regions

1.13 and later

Enterprise and Ultimate

Upgrade an ASM instance

Integration with Alibaba Cloud IDaaS for SSO and external authorization

You can now use the external authorization capability of the Service Mesh to integrate with OIDC-compliant identity providers. This enables single sign-on for applications in the mesh.

All regions

1.13 and later

Standard, Enterprise, and Ultimate

Manage Istio resources with SDKs

This release adds guides for managing Istio resources with the Go and Java SDKs.

All regions

All

Standard, Enterprise, and Ultimate

June 2022

Feature

Description

Region

References

Support for Istio 1.13.4

ASM supports Istio 1.13.4. This feature is in canary release.

All regions

None

Integration with ArgoCD, Argo Rollouts, Alibaba Cloud DevOps, and Flagger

ASM integrates with systems such as ArgoCD, Argo Rollouts, Alibaba Cloud DevOps, and Flagger to enable blue-green or canary releases for application services based on traffic management.

All regions

Support for Knative and traffic-based auto scaling

ASM supports the installation and deployment of Knative and provides traffic-based auto scaling. This allows you to use Knative without maintaining Istio.

All regions

Serverless containers and traffic-based auto scaling

Support for AI services on KServe

ASM supports AI services based on KServe, enabling capabilities like blue-green releases, canary releases, and traffic splitting between revisions for model services. It also supports serverless inference workloads with auto scaling, high scalability, and concurrency-based intelligent load routing.

All regions

Run AI services based on KServe

Integration with Application Load Balancer (ALB) through an ingress gateway

ASM supports integration with Application Load Balancer (ALB) by using an ingress gateway, making ASM available to ALB users.

All regions

Integrate an ASM ingress gateway with an Application Load Balancer (ALB) instance

Enhanced observability

You can enable mesh topology, Prometheus monitoring, the log center, and log dashboards for an ASM instance with a single click. The status of these features is displayed, and you are notified of any errors. This improves integration and the user experience for observability.

All regions

None

Enhanced traffic management

  • Trafficlabel supports the use of getHeader(key) to obtain a traffic identifier from the request header based on any custom header_key.

  • Regular expressions are supported for matching rules in delegated VirtualServices.

  • The local throttling feature is enhanced. You can add custom headers and a custom response body.

All regions

Configure local throttling on an ingress gateway

Support for synchronizing namespaces and tags from Kubernetes clusters to the global namespace

ASM supports synchronizing namespaces and tags from Kubernetes clusters to the global namespace, enabling a two-way synchronization mechanism.

All regions

None

May 2022

Feature

Description

Region

References

Manage ASM instances with Terraform.

You can now use Terraform to create and upgrade ASM instances, and manage RAM permissions.

All regions

Use Terraform to manage ASM instances

Support for Istio 1.12.4

This release introduces a service management module for streamlined service and policy configuration. It also adds a mesh topology tool for visualizing service behavior.

All regions

Support for the Istio CNI plug-in

ASM now supports the CNI plug-in to redirect traffic during pod network setup. This eliminates the need for the NET_ADMIN capability, improving your mesh's security.

All regions

Enable the CNI plug-in to enhance security

Configure a sidecar proxy using annotations

You can now configure sidecar proxies using annotations. This lets you modify proxy resources and configurations at the global, namespace, and workload levels for more flexible and fine-grained management.

All regions

Configure a sidecar proxy using annotations

Enhanced mesh diagnosis

This release adds more diagnostic rules, helping you identify and locate a wider range of mesh issues more efficiently.

All regions

Use ASM mesh diagnosis

Enhanced observability

ASM enhances observability with a unified dashboard for log monitoring, improved Prometheus integration, and an optimized mesh topology.

All regions

Enable mesh topology to improve observability

April 2022

Feature

Description

Region

References

Commercial release

ASM launched its commercial Enterprise and Ultimate Editions on April 1, 2022.

All

Billing

Envoy filter marketplace

ASM now supports end-to-end integration of Envoy filter templates. You can bind these templates to a workload to create custom Envoy filter extensions.

All

Create an Envoy filter from a template

Associate or disassociate an EIP with an API server

You can now bind an EIP to an internal API server to create a public endpoint. You can also rebind or unbind an EIP from the API server.

All

N/A

Enhanced capabilities for ASM gateways

ASM gateways now offer enhanced capabilities, including graceful shutdown for Classic Load Balancer (CLB) connections, IPv6 support, certificate management, and improved operations. You can now retain the CLB for a gateway, obtain the real client IP, and expose gateway services through various CLB types.

All

Enhanced security capabilities

  • New RBAC roles are now available to refine mesh management permissions, and an Authorization Information page has been added to display users with permissions for the current mesh.

  • The external authorization feature is enhanced, allowing you to configure header overwrites for both successful and failed authentications when using an HTTP-based external authorization service.

  • ASM now supports fine-grained RAM authorization for flexible permission control.

All

Enhanced O&M capabilities

The ASM console now detects alert rules that you have configured for the Pilot load balancer. You can also navigate directly from the ASM console to the monitoring page of the Pilot load balancer.

All

N/A

March 2022

Feature

Description

Region

References

Control the scope of OPA proxy injection

Use the opa-istio-injection label on a namespace to control the injection scope of OPA proxies. This decouples the OPA proxy from the Istio proxy's automatic injection policy, providing greater control over where OPA is enabled.

All regions

Control the injection scope of OPA sidecar proxies

Domain name and certificate management

Use cert-manager to issue a certificate for an ASM gateway, enabling you to access a service through the gateway over HTTPS.

All regions

Manage gateway certificates with cert-manager

EnvoyFilter marketplace update

ASM now provides end-to-end support for binding EnvoyFilter templates to workloads, enabling you to create custom EnvoyFilter extensions. Use the following pre-built templates or develop your own:

  • Enable support for Spring Cloud services

  • Log the HTTP body in the access log

  • Preserve the case of request and response headers

  • Set allow_connect to true to allow protocol upgrades

  • Add request header information to a response header

  • Add an HTTP response header

All regions

None

February 2022

Feature

Description

Region

References

Support for Istio 1.12 and Kubernetes 1.22

ASM now supports Istio 1.12 and Kubernetes 1.22.

All regions

None

Create an Envoy filter from an Envoy filter template

A new plug-in center in the ASM console lets you create and manage Envoy filters using Envoy filter templates.

All regions

Create an Envoy filter from an Envoy filter template

Local throttling

ASM provides a local throttling feature to limit traffic to gateways and services.

All regions

Configure local throttling on an ingress gateway

January 2022

Feature

Description

Region

References

ASM gateway updates

  • ASM now provides a details and configuration page for each ASM gateway.

  • You can now associate an ASM gateway with an upstream service and create a corresponding traffic policy.

All regions

None

Enhanced ASM Professional Edition features

  • Ensures no loss of CLB traffic when a replica instance of an ASM gateway node is taken offline.

  • You can now deploy a gateway to instance types that support Multi-Buffer for TLS acceleration.

All regions

None

Spring Cloud service management

ASM now supports managing Spring Cloud services.

All regions

Manage Spring Cloud services

New regions available

ASM is now available in the China (Guangzhou), China (Hohhot), China (Heyuan), and India (Mumbai) regions.

China (Guangzhou), China (Hohhot), China (Heyuan), India (Mumbai)

None

Support for Istio 1.11.5

ASM now supports Istio 1.11.5.

All regions

None

December 2021

Feature

Description

Region

References

Flexible external authorization

You can now declare an external authorization service in a Service Mesh and apply an authorization policy to enable more flexible external authorization.

All regions

Implement custom authorization with the gRPC protocol

Automatic Sidecar resource recommendations based on access log analysis

You can use a Sidecar resource to configure a sidecar proxy on a workload to interact only with its dependent services. This configuration can be automatically recommended based on access log analysis.

All regions

Use Sidecar resources automatically recommended based on access log analysis

Global and namespace-level sidecar proxy configuration

ASM now supports configuring the sidecar proxy at the global and namespace levels.

All regions

Configure namespace-level sidecar proxies

Custom metrics

ASM now supports defining custom metrics at the mesh, namespace, and workload levels for targeted monitoring.

All regions

Customize metrics in ASM

New dashboards for gateways and the global mesh

From the mesh details page, navigate to Observability Management Center > Prometheus Monitoring. The Prometheus Monitoring page now provides new dashboards for monitoring gateways and the global mesh.

Note

This feature is available only for Istio 1.10 and later.

All regions

None

Support for Istio 1.10.5

ASM now supports Istio 1.10.5.

All regions

None

November 2021

Feature

Description

Region

References

TLS acceleration with Multi-Buffer.

Intel Multi-Buffer optimizes the performance of TLS encryption and decryption to accelerate encrypted communication between application services.

All regions

Enable multi-buffer for TLS acceleration

Selective service discovery.

Mesh administrators can now use a global mesh configuration to optimize service discovery. This directs the control plane to discover and process only application services within specified namespaces.

All regions

Improve push efficiency with service discovery selectors

Improved stability for gateway updates.

In the ASM console, you can now view an ASM gateway's version and manually update it on the Upgrade Gateway page. This process improves update stability.

All regions

None

Gateway and data plane logs

Access the log center from the observability page in the ASM console to view detailed logs for ASM gateways and the data plane.

All regions

None

New diagnostic check for external Envoy filters.

The mesh diagnostics feature now includes a check for external Envoy filters in the control plane.

All regions

None

October 2021

Feature

Description

Region

References

Istio resource version history

When you update the spec of an Istio resource, ASM automatically saves its version history. ASM stores up to five recent versions, allowing you to roll back the resource to a previous version.

All regions

Roll back an Istio resource

Access Istio resources through the data plane Kubernetes API

You can now use a data plane cluster's Kubernetes API to access Istio resources managed by ASM. This lets you use the cluster's kubeconfig file to install, update, and uninstall Helm charts that contain Istio resources.

All regions

Access Istio resources via the data plane KubeAPI

Cross-region failover and traffic distribution

You can now distribute traffic across multiple regions by routing requests to different clusters based on specified weights. For disaster recovery, you can also configure cross-region failover to automatically redirect traffic from a disrupted region to healthy ones.

All regions

Disaster recovery for multi-VPC clusters with CEN

Control plane log collection and alerting

You can now collect logs and configure alerts for the control plane. For example, you can capture logs related to configuration pushes from the ASM control plane to data plane sidecars.

All regions

Enable control plane log collection and alerting (ASM versions earlier than 1.17.2.35)

Prometheus monitoring integration

The ASM console is now integrated with Prometheus monitoring, allowing you to view detailed traffic metrics for services and workloads on the data plane.

All regions

None

ASM gateway enhancements

  • The gateway creation page is enhanced.

    You can now select a gateway specification and specify the number of replicas.

  • Horizontal Pod Autoscaler (HPA) is disabled by default. For ASM Professional Edition, you can configure an HPA based on CPU and memory metrics.

  • IstioGateway syntax checking is enabled by default to ensure valid resource definitions.

All regions

None

Enhanced access log collection

You can now create a new Project or use an existing one for access log collection.

All regions

None

September 2021

Feature

Description

Region

References

asmctl command-line tool

The asmctl diagnostic tool detects configuration issues in ASM.

All regions

Graphical OPA policy management

You can now create and manage OPA policies in the ASM console.

All regions

Use OPA policies for fine-grained access control

Delegate RBAC permissions

A RAM user can now grant RBAC permissions to other RAM users.

All regions

None

Customizable access logs

You can now enable or disable access logs and customize their format.

All regions

Customize data plane access logs

Cross-origin resource sharing (CORS)

You can add the corsPolicy field to the VirtualService for a service to allow cross-origin requests and enable cross-origin communication.

All regions

Implement CORS in ASM

Graphical rule creation

You can now create destination rules and gateway rules graphically.

All regions

None

August 2021

Feature

Description

Region

References

Zero-trust security capabilities

This release adds several zero-trust security capabilities to enhance application security. These include peer authentication, request authentication, Istio authorization policies, and fine-grained permission control based on OPA.

All regions

None

ASM gateway enhancements

ASM gateways now include the following enhancements:

  • You can now customize hostNetwork and dnsPolicy.

  • Supports rolling updates to ensure lossless traffic during online scaling. (This feature is available only in the ASM Professional Edition).

  • Gateway high availability is now configurable.

  • Custom access logs are now supported.

All regions

ASM console enhancements

The ASM console has been improved. You can now graphically configure security policies and virtual service rules, define custom resources using YAML templates, and use the optimized management page for automatic sidecar injection.

All regions

Configure sidecar injection policies

ASM observability enhancements

  • Mesh Topology is upgraded to v1.34.

  • Mesh Topology now retrieves monitoring metrics from Managed Service for Prometheus over the internal network instead of the Internet.

  • The Logstore for sidecar logs no longer includes gateway logs. These logs are now stored exclusively in the gateway's own Logstore.

  • We have optimized the observability dashboards to resolve null-value issues in reports such as top 10 provinces, top 10 cities, Top URL, and Top IP.

All regions

July 2021

Feature

Description

Region

References

Support for multiple Consul service registries

ASM now supports connecting to multiple Consul service registries.

All regions

Connect to a Consul service registry

Dynamic updates for OPA policies

The authorization mechanism for the Service Mesh now supports dynamic updates for OPA policies.

All regions

Dynamically update OPA policies in ASM

June 2021

Feature

Description

Region

References

Service mesh governance for ACK Edge clusters

ASM now supports ACK Edge clusters, enabling Service Mesh use cases in edge computing scenarios over 5G networks. ASM now provides unified governance for services across all cloud-native, heterogeneous computing infrastructures.

All regions

None

Five new checks for mesh diagnostics

The mesh diagnostics feature now includes the following five checks:

  • Checks if the namespace injection label on the data plane is synchronized with the control plane.

  • Checks if a gateway pod uses a port below 1024.

  • Checks if the namespace of a destination rule is valid.

  • Checks if the secret for a certificate referenced by a gateway is of the correct type.

  • Checks if the secret for a certificate referenced by a gateway exists.

All regions

Use ASM mesh diagnostics

May 2021

Feature

Description

Region

References

Canary release for routing rules

ASM Professional Edition supports canary releases for routing rule configurations. It uses an extended custom resource definition (CRD), ScopeConfig, to gradually apply configurations, such as VirtualService and EnvoyFilter, to Envoy nodes. Two canary strategies are available:

  • Selector mode: This mode applies the configuration to pods that match a specific label. To use this mode, you must add the label to the target pods.

  • RollingUpdate mode: This mode applies the configuration to Envoy nodes in batches. Istio divides the nodes into a specified number of batches and rolls out the configuration to each batch sequentially.

This capability reduces the risks of changing routing rule configurations. You can also use this feature with Microservices Engine (MSE) to implement canary releases.

All regions

This feature is discontinued.

April 2021

Feature

Description

Region

References

VirtualService delegation

ASM now supports VirtualService delegation, allowing you to split a service's routing rules into separate resources. This reduces the risk of modifying complex routing rules.

All regions

Use VirtualService delegation in ASM

GZIP data compression

You can now enable GZIP data compression for an ASM gateway. When enabled, the gateway compresses HTTP responses to speed up responses and reduce traffic.

All regions

Enable compression for an ASM gateway

WebAssembly (Wasm)-based Service Mesh instance extension

WebAssembly (Wasm) extends the ASM data plane. You can enable the WebAssembly-based Service Mesh instance extension in the console.

All regions

Use ORAS to simplify Wasm-based Service Mesh instance extensions

March 2021

Feature

Description

Region

References

DNS proxy support.

An ASM instance uses Kubernetes services and defined ServiceEntries to push hostname-to-IP-address mappings for all accessible services. When a Service Mesh receives a DNS query from an application, the Istio proxy transparently intercepts the query and resolves the request.

You can enable or disable the DNS proxy in Service Mesh by using the console or the Alibaba Cloud CLI. This can significantly improve the performance and availability of the mesh.

All regions

Use a DNS proxy in ASM

Kernel parameter tuning for ingress gateways.

You can tune the kernel parameters for ingress gateways. This provides more flexibility to optimize performance.

All regions

ASM gateway CRD description

Read-only configurations can be enabled for CLB instances created by Service Mesh.

The API server and Pilot CLB created by Service Mesh have read-only configurations enabled by default. This prevents accidental operations, such as modifications or deletions, and improves the availability of the Service Mesh product.

All regions

None

Namespace synchronization between the control plane and data plane.

To improve usability, ASM now synchronizes namespaces between the control plane and the data plane. When you add a Kubernetes cluster to an ASM instance, ASM automatically synchronizes its namespaces to the cluster. The ASM console also provides a manual synchronization option.

All regions

None

February 2021

Feature

Description

Region

References

Service Mesh is generally available in 12 regions, supports Istio 1.8.3, and integrates with ACK Serverless clusters and Elastic Container Instance (ECI) pods on ACK.

  • Supports Istio 1.8.3.

  • Integrates with ACK Serverless clusters and Elastic Container Instance (ECI) pods on ACK.

  • Supports a service-linked role.

  • Is generally available in 12 regions.

All regions

Enhances ingress gateway lifecycle management and adds support for custom gateways.

  • Supports CRD-based management of custom gateways.

  • Supports TLS passthrough and Secret Discovery Service (SDS) for ingress gateways.

All regions

Create and manage an ingress gateway by using the Kubernetes API

Supports connecting to multiple service registries, simplifying microservice migration to Service Mesh.

  • Supports connecting to a Consul service registry, simplifying microservice migration to Service Mesh.

All regions

Connect to a Consul service registry

Supports WebAssembly (Wasm) for simplified service mesh extensions.

Service Mesh now supports OCI Registry as Storage (ORAS), simplifying Wasm-based Service Mesh extensions.

All regions

Use ORAS to simplify Wasm-based service mesh extensions

January 2021

Feature

Description

Region

References

New regions available

ASM is now available in the China (Chengdu) region on the China site and the US (Virginia) region on the international site.

All

None

One-click observability setup

To improve observability, ASM now lets you enable access log collection, Managed Service for Prometheus, and mesh topology with a single click.

All

HTTP/1.0 protocol support

By default, Envoy requires upstream services to use HTTP/1.1 or HTTP/2.0. ASM now lets you enable HTTP/1.0 with a single click to ensure compatibility with legacy systems.

All

None

Ingress gateway and update process enhancements

  • The ingress gateway definition is improved. It now supports the nodeSelector field and provides a standard way to use annotations to configure CLB instances for ingress gateways.

  • Optimized configuration update and version upgrade processes for ASM instances reduce wait times and improve the user experience.

  • Validation for envoy filter custom resources is improved.

All

None

November 2020

Feature

Description

Region

References

Istio 1.7.5 support and availability on the international site

ASM now supports Istio 1.7.5 and is available on the international site.

All regions

None

Istio CNI plug-in support

ASM now supports the Istio CNI plug-in for instances running Istio 1.7 or later. The plug-in replaces the istio-init container and eliminates the need for elevated privileges, enhancing security.

All regions

Due to conflicts with other CNI plug-ins, this feature is discontinued and is pending re-evaluation.

Mesh topology

Mesh topology provides a web-based graphical user interface (GUI) to view the health of your Service Mesh.

All regions

None

Hot upgrade for the data plane (Beta)

ASM now supports hot upgrades for the data plane, allowing you to upgrade an ASM instance's data plane without service interruptions or application impact.

All regions

None

October 2020

Feature

Description

Region

References

Flexible methods to enable automatic injection.

ASM supports multiple flexible methods for enabling automatic injection:

Note

Your ASM instance must be version 1.6.8.19 or later.

  • You can enable automatic injection for all namespaces with a single click.

  • You can use a pod annotation to control the sidecar injection policy.

  • You can use alwaysInjectSelector and neverInjectSelector to control the sidecar injection policy in specific scenarios.

All regions

Configure sidecar injection policies

Kubernetes 1.18 support on the data plane.

The ASM data plane now supports Kubernetes clusters running version 1.18, including all supported versions of ACK clusters.

Note

Your ASM instance must be version 1.6.8.19 or later.

All regions

None

September 2020

Feature

Description

Region

References

Support for Istio 1.6.8

ASM now supports Istio version 1.6.8 and provides full support for ACK-on-ECI and ACK Serverless clusters. With this update, ASM provides unified support for various types of computing infrastructure, including dedicated ACK clusters, managed ACK clusters, ACK Serverless clusters, ACK-on-ECI, ECI, ECS, and registered external clusters.

All regions

None

Enhanced Mixerless Telemetry V2

ASM enhances Mixerless Telemetry V2 to non-intrusively generate telemetry data from service traffic within the service mesh. You can use these ASM metrics to automatically scale workloads.

All regions

Scale workloads based on ASM traffic metrics

Mesh diagnostics

ASM now supports mesh diagnostics for an ASM instance. These diagnostics check data plane versions, service ports, service associations, app and version labels, destination addresses, and virtual service conflicts. This feature simplifies the operation and maintenance of your Service Mesh.

All regions

Use ASM mesh diagnostics

August 2020

Feature

Description

Region

References

Cluster domain setting

When you create an ASM instance, you can now specify a cluster domain. The default cluster domain is cluster.local. If you add an ACK cluster that uses a custom domain to the mesh, you must set the cluster domain of the ASM instance to match.

All regions

None

Support for ACK Serverless clusters

You can now add ACK Serverless clusters to Service Mesh. This lets you apply unified traffic management to workloads running on elastic container instances.

All regions

None

July 2020

Feature

Description

Region

References

General availability of Service Mesh

Alibaba Cloud Service Mesh (ASM) is a fully managed Service Mesh platform that is compatible with the open source Istio Service Mesh. ASM simplifies service governance by providing features such as traffic routing and splitting, secure inter-service communication, and mesh observability. This significantly reduces development and O&M workloads. ASM is designed for core scenarios, such as hybrid clouds, multi-cloud environments, multi-cluster architectures, and the migration of non-containerized applications. It provides a unified and managed Service Mesh with the following capabilities:

  • Unified management

  • Unified traffic management

  • A fully managed control plane

    ASM is currently free of charge. You are billed only for associated resources, such as ACK clusters, CLB instances, and Simple Log Service.

China (Beijing), China (Hangzhou), China (Zhangjiakou), China (Shanghai), China (Shenzhen), Indonesia (Jakarta), and Germany (Frankfurt). Support for additional regions is being rolled out.

None

Export tracing data to a self-managed system

ASM supports exporting tracing data to Managed Service for OpenTelemetry and to self-managed systems that are compatible with the Zipkin protocol.

All regions

Export ASM tracing data to a self-managed system

Support for registered clusters

You can register an external Kubernetes cluster in the ACK console and manage its applications with Service Mesh (ASM).

All regions

Manage applications in a registered cluster with ASM